CVE-2024-12109: Product Labels For Woocommerce < 1.5.9 - Admin+ SQLi
Published Mar 25, 2025
·Updated
The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Affected Software
2 affected components
WordPress Product Labels For Woocommerce<1.5.9
acowebs Product Labels For Woocommerce \(sale Badges\) Wordpress<1.5.9
Event History
Mar 25, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12109?
CVE-2024-12109 has been classified as a critical vulnerability due to the potential for SQL injection attacks.
2
How do I fix CVE-2024-12109?
To fix CVE-2024-12109, update the Product Labels For WooCommerce plugin to version 1.5.9 or later.
3
Who is affected by CVE-2024-12109?
Individuals using versions of the Product Labels For WooCommerce plugin prior to 1.5.9 are affected by CVE-2024-12109.
4
What type of attack can CVE-2024-12109 facilitate?
CVE-2024-12109 can facilitate SQL injection attacks which may compromise the database integrity.
5
Is CVE-2024-12109 fixed in future releases?
Yes, CVE-2024-12109 is fixed in version 1.5.9 and subsequent releases of the plugin.